Trust & Privacy

Your documents. Your data. Your control.

Recitare is built privacy-first: encrypted storage, automatic PII redaction, no AI training on your content, and delete-anytime control.

PII Auto-RedactedNo AI TrainingTLS 1.2+ EncryptedFull Audit Trail

How Max Protects Your Data

Six layers of protection built into every interaction.

PII Privacy Shield

Max automatically scans for sensitive data (Social Security and National Insurance numbers, phone numbers in US, UK and international formats, email addresses, credit cards, IBANs, street addresses and postcodes) and replaces it with [PROTECTED] placeholders before your text is sent for AI analysis: questions, summaries, and study guides. For documents about other people, optional Name Protection hides personal names too. (Text sent for speech synthesis is spoken exactly as written, so it is protected by our providers' no-training terms rather than redaction.)

No AI Model Training

Your documents are not used to train Google Gemini, Anthropic Claude, or any other AI model — their API terms prohibit training on submitted data. For repeat questions on the same document, text may be briefly cached by the AI provider (up to ~30 minutes) to speed up responses, then discarded.

Encrypted in Transit & at Rest

All data transmitted between your browser and our servers uses TLS 1.2+ encryption. Documents stored in our database are encrypted at rest. Your content travels through secure channels at every step.

Your Activity, Visible to You

You can review a complete history of every AI action on your documents — what ran, when, and with which model — anytime from your account. Built so YOU can verify what Max did, not so we can watch you.

Your Data, Your Control

Delete any document, summary, or your entire account at any time. Deleted items enter a 30-day recovery window, then are permanently erased — documents, cached audio, and AI outputs alike. Your subscription, your data, your rules.

Verified AI Outputs

Max cites specific page numbers when generating summaries and study guides. Every claim links back to your source document, so you can verify Max’s work — not just trust it.

For interviews and participant data

Name Protection

Pattern matching can recognise a phone number. It cannot recognise a name. For transcripts and other documents about real people, tick Protect names in this document when you upload, or switch it on later from the More menu in the reader.

  1. 1

    Names are found on your device

    A small language model runs inside your browser and picks out the personal names. Your document is not sent anywhere for this step. The model is downloaded once from Hugging Face, then kept in your browser.

  2. 2

    AI analysis sees tokens, not names

    Before a question, summary, study guide or library search goes to our AI providers, each name is swapped for a neutral token such as [PERSON_3fa9c1b20d4e].

  3. 3

    You still see the real names

    The swap happens on our server, at the single point where text leaves for an AI provider, and the names are put back before the answer reaches you. The list of names is stored with your document, which already contains them, and is deleted with it.

What it does not cover

  • Read-aloud. Speech synthesis has to receive the text as written, so names are spoken. That text is covered by our providers' no-training terms instead.
  • Pictures. A Snap sends an image of the area you select, and text inside an image cannot be swapped out. Max asks before the first Snap on a protected document.
  • Your stored document. It is kept encrypted with the names intact, so that you can read it. You can delete it at any time.
  • Missed names. Detection is tuned for English and can miss unusual names or spellings. Treat it as a safeguard alongside your ethics approval, not as a substitute for anonymising data your protocol requires you to anonymise.
  • A short wait at the start. Until the names have been found, usually a minute or two after upload, Max pauses AI features on all your documents rather than run anything unprotected. Scanned pages of a protected upload are read on your device instead of by a cloud model, which is slower, and figure descriptions are skipped.
  • Switching it on later. Protection starts from that moment. Anything the document already sent for AI analysis cannot be recalled.

What We Use & Why

Every AI provider we work with is held to strict data handling standards.

Provider

Google Gemini

Purpose

Document analysis, summaries, study guides, chat

Data Policy

1M token context; not used to train models

Provider

Inworld

Purpose

Text-to-speech for all listening tiers

Data Policy

Real-time synthesis, not used for model training

Provider

Anthropic Claude

Purpose

Image and diagram analysis (OCR)

Data Policy

Not used to train models

Our Privacy Commitments

Clear promises, no fine print.

We never sell your data — period.

AI providers do not train on your content by default.

Automatic PII redaction runs before AI analysis, and optional Name Protection hides personal names too.

You can export or delete your data at any time.

Frequently Asked Questions

Common questions about privacy, security, and how Max handles your data.

Questions about security?

We’re happy to walk you through our architecture and data handling practices.